7.2
CVSSv2

CVE-2015-6923

Published: 21/09/2015 Updated: 09/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.

Vulnerable Product Search on Vulmon Subscribe to Product

vboxcomm satellite express protocol 2.3.17.3

Exploits

KL-001-2015-005 : VBox Satellite Express Arbitrary Write Privilege Escalation Title: VBox Satellite Express Arbitrary Write Privilege Escalation Advisory ID: KL-001-2015-005 Publication Date: 20150916 Publication URL: wwwkorelogiccom/Resources/Advisories/KL-001-2015-005txt 1 Vulnerability Details Affected Vendor: VBox Communi ...
A vulnerability within the ndvbs module allows an attacker to inject memory they control into an arbitrary location they define This vulnerability can be used to overwrite function pointers in HalDispatchTable resulting in an elevation of privilege suffers from code execution, and local file inclusion vulnerabilities ...